Categories: Malware

Malware.AI.3681935632 removal guide

The Malware.AI.3681935632 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3681935632 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Dynamic (imported) function loading detected
  • Unconventionial language used in binary resources: Korean
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine Malware.AI.3681935632?


File Info:

name: A97BBFFAC5C1CDD7777A.mlwpath: /opt/CAPEv2/storage/binaries/db3b964391db709b7bd73ae2a3714ca9830dbeb4ac9d7e2dd6f7db3641548b75crc32: 76527436md5: a97bbffac5c1cdd7777af93da252efe4sha1: 6df28232ec01f2a7996dd51094fe42afe8180ec1sha256: db3b964391db709b7bd73ae2a3714ca9830dbeb4ac9d7e2dd6f7db3641548b75sha512: 02afc92ae3312b03ca2ce1e5a6e0be2cb92e89eaf35a2ea1fcdb118498f8b3ab8105676fc670cd7e132cf2e4f8827484308e48386d452086f85a5fea27fcced4ssdeep: 384:iTIx1aXMmwtyrQFLm+2fjGBm338VkwoA8S/m/MKOuBwV0M+VxbooLTm7qhOJCY9d:LDh0k+yBm3MOBD/bM+VzLKXJ/5Btype: PE32 executable (GUI) Intel 80386, for MS Windowstlsh: T19A2360E1F6F30411E56AC6350AAEC3A74263A8543A1247DA3217AE3849FEF31347D6D3sha3_384: 194fd2570d23a96b4a9d818278bd73562e882c0cb26f43b36397aaccc954c2dd9b5133fc52ea672fc1c65a3111ea0631ep_bytes: 681014a700e8eeffffff000000000000timestamp: 2015-04-12 04:57:34

Version Info:

Translation: 0x0412 0x04b0Comments: Windows 탐색기CompanyName: Microsoft CorporationFileDescription: Windows 탐색기LegalCopyright: ⓒ Microsoft Corporation. All rights reserved.LegalTrademarks: ⓒ Microsoft CorporationProductName: Microsoft® Windows® Operating SystemFileVersion: 6.01.7601ProductVersion: 6.01.7601InternalName: explorerOriginalFilename: explorer.exe

Malware.AI.3681935632 also known as:

Bkav W32.AIDetect.malware2
Elastic malicious (high confidence)
MicroWorld-eScan Gen:Trojan.Heur.dm1@Xu1GmycG
ALYac Gen:Trojan.Heur.dm1@Xu1GmycG
Cylance Unsafe
Zillya Worm.VBNA.Win32.235910
Sangfor Trojan.Win32.Save.a
K7AntiVirus Riskware ( 0040eff71 )
K7GW Riskware ( 0040eff71 )
CrowdStrike win/malicious_confidence_100% (D)
Baidu Win32.Worm.VB.ru
Cyren W32/Shark.A.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Win32/TrojanDownloader.VB.QVP
APEX Malicious
Kaspersky Worm.Win32.VBNA.c
BitDefender Gen:Trojan.Heur.dm1@Xu1GmycG
Avast Win32:VB-AAHT [Trj]
Tencent Malware.Win32.Gencirc.114ccc34
Ad-Aware Gen:Trojan.Heur.dm1@Xu1GmycG
Emsisoft Gen:Trojan.Heur.dm1@Xu1GmycG (B)
DrWeb Trojan.DownLoader12.60398
FireEye Generic.mg.a97bbffac5c1cdd7
Sophos ML/PE-A
SentinelOne Static AI – Malicious PE
GData Gen:Trojan.Heur.dm1@Xu1GmycG
Jiangmin Worm.VBNA.dycp
Avira TR/VB.Downloader.Gen
Antiy-AVL Trojan/Generic.ASMalwS.101997F
Arcabit Trojan.Heur.E03D8B
Microsoft Trojan:Win32/Sabsik.FL.B!ml
Cynet Malicious (score: 99)
AhnLab-V3 Worm/Win32.VBNA.R142786
MAX malware (ai score=83)
VBA32 Trojan.FakeExplorer.bv
Malwarebytes Malware.AI.3681935632
Rising Trojan.Generic@ML.91 (RDML:NNe0mFZiEPyzR98qAYsw0g)
Ikarus Trojan.SuspectCRC
eGambit Unsafe.AI_Score_94%
BitDefenderTheta AI:Packer.2BDCAA4D1C
AVG Win32:VB-AAHT [Trj]
Cybereason malicious.ac5c1c

How to remove Malware.AI.3681935632?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

Malware.AI.4183435755 information

The Malware.AI.4183435755 is considered dangerous by lots of security experts. When this infection is active,…

3 mins ago

Dropped:Application.Generic.3571726 removal instruction

The Dropped:Application.Generic.3571726 is considered dangerous by lots of security experts. When this infection is active,…

7 mins ago

What is “Trojan.Generic.35245150”?

The Trojan.Generic.35245150 is considered dangerous by lots of security experts. When this infection is active,…

13 mins ago

Malware.AI.1658877817 removal tips

The Malware.AI.1658877817 is considered dangerous by lots of security experts. When this infection is active,…

18 mins ago

About “Win32/Pronny.JI” infection

The Win32/Pronny.JI is considered dangerous by lots of security experts. When this infection is active,…

29 mins ago

Adware.Ursu.14752 removal

The Adware.Ursu.14752 is considered dangerous by lots of security experts. When this infection is active,…

39 mins ago